Описание
In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to read the content of files on the host's filesystem, given their path, without restrictions on the requester's origin. This design is vulnerable to being exploited remotely through a DNS rebinding attack or a drive-by download of a carefully crafted exploit.
Ссылки
- ExploitIssue TrackingVendor Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.3.9 (включая) до 0.15.0 (включая)
cpe:2.3:a:eclipse:theia:*:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.0012
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-345
CWE-345
Связанные уязвимости
CVSS3: 8.1
github
почти 5 лет назад
Insufficient Verification of Data Authenticity in Eclipse Theia
EPSS
Процентиль: 31%
0.0012
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-345
CWE-345